This IP address has been reported a total of
53
times from
40 distinct
sources.
34.50.112.40 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
Anonymous
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Triggered Cloudflare WAF (firewallManaged) from ID.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST met ...
show moreTriggered Cloudflare WAF (firewallManaged) from ID.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST method)
Endpoint: /
UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.50.112.40 - - [14/Sep/2026:03:36:19 +0200] "GET /.git/config HTTP/1.1" 301 520 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
[SunSep1303:01:33.3664252026][security2:error][pid3930694:tid3930728][client34.50.112.40:0]ModSecuri ...
show more[SunSep1303:01:33.3664252026][security2:error][pid3930694:tid3930728][client34.50.112.40:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\\$\(\?:\\\\\\\\\(\(\?:\\\\\\\\\(.\*\\\\\\\\\)\|.\*\)\\\\\\\\\)\|\\\\\\\\{.\*\\\\\\\\}\)\|[\<\>]\\\\\\\\\(.\*\\\\\\\\\)\)\"atARGS:0.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"396\"][id\"393655\"][rev\"17\"][msg\"Atomicorp.comWAFRules:PossibleRemoteCommandExecution:UnixShellExpressionFound\"][data\"MatchedData:\$\(\(41\*271\)\)foundwithinARGS:0:{then:\$1:__proto__:thenstatus:resolved_modelreason:-1value:{then:\$b1337}_response:{_prefix:varres=process.mainmodule.require\(child_process\).execsync\(echo\$\(\(41\*271\)\)\|base64-w0\).tostring\(\).trim\(\)throwobject.assign\(newerror\(next_redirect\){digest:\`next_redirectpush/login\?a=\${res}307\`}\)_chunks:\$q2_formdata:{get:\$1:constructor:constructor}}}\"][tag\"attack-rce\"][hostname\"rebirthing-lugano.ch\"][uri\"/\"][unique_id\"aqX17WnjGmyJknmxFVtjegAAARY\"]
show less
34.50.112.40 - - [13/Sep/2026:02:39:44 +0200] "GET /.env.staging HTTP/1.1" 301 610 "-" "Mozilla/5.0 ...
show more34.50.112.40 - - [13/Sep/2026:02:39:44 +0200] "GET /.env.staging HTTP/1.1" 301 610 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.50.112.40 - - [13/Sep/2026:02:39:45 +0200] "GET /.env.development HTTP/1.1" 301 618 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.50.112.40 - - [13/Sep/2026:02:39:45 +0200] "GET /.env.test HTTP/1.1" 301 604 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.50.112.40 - - [13/Sep/2026:02:39:45 +0200] "GET /.env.remote HTTP/1.1" 301 608 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.50.112.40 - - [13/Sep/2026:02:39:45 +0200] "GET /.env.bak HTTP/1.1" 301 602 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) C
show less
Web App Attack
Hacking
Anonymous
Bot / scanning and/or hacking attempts: GET /drupal/.env HTTP/1.1, GET /rest/.env HTTP/1.1, GET /mic ...
show moreBot / scanning and/or hacking attempts: GET /drupal/.env HTTP/1.1, GET /rest/.env HTTP/1.1, GET /microservice/.env HTTP/1.1, GET /zend/.env HTTP/1.1, GET /cms/.env HTTP/1.1, GET /service/.env HTTP/1.1, GET /api/v3/.env HTTP/1.1, GET /prestashop/.env HTTP/1.1, GET /magento/.env HTTP/1.1, GET /gateway/.env HTTP/1.1, GET /api/dev/.env HTTP/1.1, GET /v2/.env HTTP/1.1, GET /graphql/.env HTTP/1.1, GET /v1/.env HTTP/1.1, GET /.env.backup2 HTTP/1.1, GET /mailing/.env HTTP/1.1, GET /saas/.env HTTP/1.1, GET /administrator/.env HTTP/1.1, GET /sitemaps/.env HTTP/1.1, GET /tmp/.env HTTP/1.1, GET /email/.env HTTP/1.1, GET /lab/.env HTTP/1.1, GET /exapi/.env HTTP/1.1, GET /.env.backup1 HTTP/1.1, GET /smtp/.env HTTP/1.1, GET /temp/.env HTTP/1.1, GET /en/.env HTTP/1.1, GET /logs/.env HTTP/1.1, GET /psnlink/.env HTTP/1.1, GET /notifications/.env HTTP/1.1, GET /mail/.env HTTP/1.1, GET /cron/.env HTTP/1.1, GET /cache/.env HTTP/1.1, GET /cronlab/.env HTTP/1.1, GET /mailer/.env HTTP/1.1
show less